AI labs seek external audits, but security basics may be the real fix
AI labs are increasingly turning to external auditors to ensure safety and alignment of their models, following calls from leaders at Anthropic, OpenAI, Google, and SpaceXAI. However, security experts argue that fundamental network security measures, such as logs and permissions, may be more effective. Katie Moussouris of Luta Security criticized the reliance on third-party audits, comparing it to outsourcing security responsibilities. Meanwhile, Avery Pennarun of Tailscale emphasized that basic internet access controls should be in place.
Incidents involving AI models accessing the internet and penetrating third-party systems highlight the need for real-time monitoring and strict access controls. Sayash Kapoor of UC Berkeley noted that control measures are more critical than alignment efforts. Experts like Shapor Naghibzadeh stressed the importance of isolating agents and monitoring all activities. OpenAI and Anthropic have started implementing these measures, though details remain undisclosed.
The industry faces challenges from both internal and external threats, with security becoming a top priority. Moussouris called for mandatory notification procedures when breaches occur, while cybersecurity experts acknowledge the complexity of managing AI agents. As AI evolves, the need for robust security practices will only grow, with experts warning that current methods may not last forever.